CVE-2023-26039
published 2023-02-25CVE-2023-26039: ZoneMinder is a free, open source Closed-circuit television software application for Linux which supports IP, USB and Analog cameras. Versions prior to 1.36.33…
PriorityP355high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
1.25%
65.8th percentile
ZoneMinder is a free, open source Closed-circuit television software application for Linux which supports IP, USB and Analog cameras. Versions prior to 1.36.33 and 1.37.33 contain an OS Command Injection via daemonControl() in (/web/api/app/Controller/HostController.php). Any authenticated user can construct an api command to execute any shell command as the web user. This issue is patched in versions 1.36.33 and 1.37.33.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | zoneminder | < zoneminder 1.36.33+dfsg1-1 (bookworm) | zoneminder 1.36.33+dfsg1-1 (bookworm) |
| zoneminder | zoneminder | < 1.36.33 | 1.36.33 |
| zoneminder | zoneminder | — | — |
| zoneminder | zoneminder | >= 0 < 1.36.33+dfsg1-1 | 1.36.33+dfsg1-1 |
| zoneminder | zoneminder | >= 0 < 1.36.33+dfsg1-1 | 1.36.33+dfsg1-1 |
| zoneminder | zoneminder | >= 0 < 1.36.33+dfsg1-1 | 1.36.33+dfsg1-1 |
| zoneminder | zoneminder | >= 1.37.00 < 1.37.33 | 1.37.33 |
Detection & IOCsextracted from sources · hover to see the quote
- →OS Command Injection entry point is the daemonControl() function in the ZoneMinder API controller at the path /web/api/app/Controller/HostController.php — monitor for unexpected shell-spawning processes originating from the web user via this endpoint ↗
- →Any authenticated ZoneMinder user can trigger the injection; alert on API calls to the HostController daemonControl endpoint that include shell metacharacters or unexpected command arguments ↗
- ·Vulnerability is scoped as local exploitation (authenticated session required); unauthenticated remote exploitation is not directly possible — detection should focus on authenticated API abuse ↗
- ·Affected versions are prior to 1.36.33 and 1.37.33; Debian bullseye remains unpatched as of the advisory — prioritize detection on those deployments ↗
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv8.8HIGH
vendor_debian7.1LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2023-26039: ZoneMinder is a free, open source Closed-circuit television software application for Linux which supports IP, USB and Analog cameras
osv·2023-02-25·CVSS 8.8
CVE-2023-26039 [HIGH] CVE-2023-26039: ZoneMinder is a free, open source Closed-circuit television software application for Linux which supports IP, USB and Analog cameras
ZoneMinder is a free, open source Closed-circuit television software application for Linux which supports IP, USB and Analog cameras. Versions prior to 1.36.33 and 1.37.33 contain an OS Command Injection via daemonControl() in (/web/api/app/Controller/HostController.php). Any authenticated user can construct an api command to execute any shell command as the web user. This issue is patched in versions 1.36.33 and 1.37.33.
Debian
CVE-2023-26039: zoneminder - ZoneMinder is a free, open source Closed-circuit television software application...
vendor_debian·2023·CVSS 7.1
CVE-2023-26039 [HIGH] CVE-2023-26039: zoneminder - ZoneMinder is a free, open source Closed-circuit television software application...
ZoneMinder is a free, open source Closed-circuit television software application for Linux which supports IP, USB and Analog cameras. Versions prior to 1.36.33 and 1.37.33 contain an OS Command Injection via daemonControl() in (/web/api/app/Controller/HostController.php). Any authenticated user can construct an api command to execute any shell command as the web user. This issue is patched in versions 1.36.33 and 1.37.33.
Scope: local
bookworm: resolved (fixed in 1.36.33+dfsg1-1)
bullseye: open
forky: resolved (fixed in 1.36.33+dfsg1-1)
sid: resolved (fixed in 1.36.33+dfsg1-1)
trixie: resolved (fixed in 1.36.33+dfsg1-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-02-25
Published